Based on information from Infosecurity Magazine, the UK’s National Cyber Security Centre (NCSC) is calling on device manufacturers to enhance forensic observability in their products to aid incident response teams in evidence collection following a compromise.The NCSC highlights that network devices like firewalls and VPN gateways are increasingly targeted by attackers. Chris A, technical director at NCSC, stated that when incidents occur, organizations need reliable methods to understand what happened and assess device trustworthiness. Forensic observability, defined by the NCSC as providing telemetry, logging, configuration state, and the ability to collect forensic data from memory and at rest, is crucial for this. Manufacturers are urged to build supported mechanisms for gathering evidence, rather than defenders relying on reverse engineering or vulnerability research.The NCSC aims to dispel myths that observability aids attackers, deters customers, or is too difficult to implement, asserting that well-designed features enhance security and build trust. The agency is also collaborating with global partners to develop a reference architecture for forensic observability in network appliances.Source: Infosecurity Magazine
